Skip to content
Cloud Efficiency Hub

Unused Restored Tables in Log Analytics Workspaces

The short version

The Log Analytics restore operation brings a time range of data from long-term retention (or from any Analytics table) into the hot cache as a new table ending in _RST, so that it can be queried with full KQL at high performance.

PointFive Research

Cloud cost research at PointFive

Azure service
Azure Log Analytics
Category
Other
Reference
CER-0424
Type
Idle or Unused Resource

Explanation

Why the waste happens and who it affects.

It is typically used for incident investigations, audits and one-off analyses. Billing starts when the restore begins and continues every day until the restored table is dismissed by deleting it.

Investigators often finish their analysis and move on without deleting the _RST table, so the restore keeps billing for days or weeks with no queries against it. Because restores are billed on a minimum of 2 TB, even a small restore that is left running costs as much per day as a 2 TB one. Azure Advisor flags workspaces with active restored tables through its Consider removing unused restored tables recommendation.

Billing model

The pricing dimensions that drive this cost.

Restore is billed on the volume restored and the time the restore stays active.

Restore charge
Billed per GB per day for each UTC day the restore is active, until the _RST table is deleted
Minimum volume
Each restore is billed for at least 2 TB, even if less data is restored
Minimum duration
Each restore is billed for at least 12 hours, with partial-day billing on the first and last days
Queries
Querying a restored table has no extra charge because restored tables use the Analytics plan

How to detect

4 checks to find it in your estate.

  • Review the Azure Advisor cost recommendation Consider removing unused restored tables on microsoft.operationalinsights/workspaces resources
  • List tables in each workspace (Tables view in the portal or the Tables - Get API without a table name) and find those whose name ends in _RST and that carry restoredLogs properties
  • With query auditing enabled, search LAQueryLogs QueryText for each _RST table name; restores with no queries for several days are idle
  • In Cost Management, filter to the Log Analytics workspace and look for data restore charges on days when no investigation is open

How to fix

4 ways to remove the waste.

  • Delete the _RST table as soon as the investigation is finished; deleting a restored table stops restore billing and does not delete data in the source table
  • Restore only the time range needed, keeping in mind the 2 TB and 12-hour billing minimums, and set an owner and end date for every restore
  • Use search jobs when only records matching specific criteria are needed, and export jobs for one-time bulk extracts, instead of restoring whole time ranges
  • Set up an Azure Advisor alert on the unused restored tables recommendation so leftover restores are caught automatically

Documentation

Vendor references for pricing and configuration.